Desk live·
ForensicPost
Insurance/Enforcement/File 20-1001

Treasury Told Cyber Insurers That Paying a Sanctioned Ransomware Actor Is Their Liability Too

The Oct. 1, 2020, advisory from the Office of Foreign Assets Control named insurers, negotiators and forensics firms as parties that could violate sanctions by facilitating a payment, and reminded them the liability is strict. It changed who was in the room when a victim decided to pay.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetRansomware payment facilitators
ActorUnattributed
D. Kennedy9 min readConfidence: high3 sources reviewed

On Oct. 1, 2020, the U.S. Treasury’s Office of Foreign Assets Control issued an advisory on the sanctions risk of facilitating ransomware payments. It stated that companies that make or arrange payments on behalf of victims, including financial institutions, cyber insurance firms and digital forensics and incident response companies, may be violating OFAC regulations if the recipient is a sanctioned person or entity. The Financial Crimes Enforcement Network issued a companion advisory the same day.

The advisory listed the ransomware actors already under sanctions: Evgeniy Bogachev of CryptoLocker, two Iranian nationals tied to SamSam, the Lazarus Group behind WannaCry and Evil Corp, sanctioned in December 2019 for Dridex. It reminded readers that civil liability under the sanctions regime is strict. A payer does not need to know the recipient is sanctioned to be liable.

The Insurer Was Named On Purpose

By 2020, a ransomware payment was rarely a victim acting alone. The insurer approved it, a negotiator handled it and a forensics firm certified the decryptor. The advisory addressed that chain directly. An insurer reimbursing a payment to Evil Corp, whose Phoenix locker would hit CNA Financial six months later, filed at 21-0323, was now on notice that the reimbursement itself carried exposure.

What It Did And Did Not Do

The document imposed no penalty and created no new rule. It named mitigating factors: a risk-based compliance program, and reporting the attack to law enforcement promptly and completely. The updated version of Sept. 21, 2021, strengthened the language discouraging payment and was issued alongside the designation of SUEX, a virtual currency exchange, the first such designation over ransomware proceeds.

The practical effect was procedural. Insurers and negotiators began screening attacker wallets and personas against the sanctions list before any payment, and declining where a match or a plausible link appeared. The corpus later recorded a $22 million payment at 24-0301 and a $75 million payment at 25-0728. Neither went to a sanctioned actor, and the screening that establishes that is the advisory’s legacy.

How we reported this

Compiled from the OFAC advisory and its 2021 update, the Treasury press release on the SUEX designation and the CISA alert summarising the advisory, listed below. The advisory is guidance; no enforcement action against an insurer under it was found. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Advisory on Potential Sanctions Risks for Facilitating Ransomware PaymentsU.S. Treasury, OFAC
  2. Treasury Takes Robust Actions to Counter RansomwareU.S. Treasury
  3. Department of Treasury Releases Advisory on Potential Sanctions Risks for Facilitating Ransomware PaymentsCISA
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary